Adding an app into the account page (not admin one)

I need to add an app to the account page. (The one that is by an address *, not the admin page). My plan is to load it in an iframe. The biggest problem is to identify the current user. I can do that by using variable, but that's insecure as hell.

Is there a better way?

